This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Cannot start any anti-virus scan tools

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am trying to repair a college kid's PC. I have been trying to remove the Home Antivirus 2009 on the machine as a start of the issue, but I think there is something deeper going on here. In Safe Mode (Windows XP 2002, SP3) I will click on the antivirus icon to execute. The hour-glass will appear for a few seconds like it is about to start, but the hourglass turns off in a few seconds and I am back to a higyhlighted icon only. I followed procedures listed on his Norton AntiVirus site (this is the AV he runs), as well as forum recommendations. I have uninstalled almost everything but the problems remain.

I tried alternate solutions by downloading MalwareBytes Anti-Malware, SmitFraud, and ComboFix to see if theiy can claen the system. All share the same symptoms. ComboFix will get as far as asking if I want to run tghe app, and then show the same behavior.

Oddly enough, HijackThis works. I have never quite understood what this utility tells you security experts, but I see everyone else post the log so I will do same.

Please recommend next steps. I'm pretty tech-savvy, but this one has me stumped.

Thanks

-DM

++++++++++++++++++
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:54:29 PM, on 7/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Andy\Desktop\ComboFix.exe
C:\Documents and Settings\Andy\Desktop\JunkYard\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1242106997203
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 5311 bytes
[external image: Posted Image]

Hi DAM-D, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Please do not use any tools such as Combofix, Vundofix, or HijackThis fixes without instruction to do so!
  • Finally, stay with this topic until I give you the final 'All clear' post! :thumbup:

1) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

2) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


3) What You Will Need To Post:
  • DDS logs
  • GMER log
DDS and GMER were downloaded as requested. - DDS ran OK and created logs (see below). - GMER would not execute. It demonstrated the same behavior as described in the root post for the AV tools. -DAM-D ++++++++++++++++++++++++++++ DDS LOG (I was unable to upload) DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 8:40:32.10 on Wed 07/22/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1464 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Internet Explorer\Iexplore.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\SCardSvr.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\StacSV.exe C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\alg.exe C:\Program Files\DellTPad\Apoint.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RunDLL32.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe C:\Program Files\Wave Systems Corp\SecureUpgrade.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe C:\WINDOWS\system32\KADxMain.exe C:\Program Files\Digital Line Detect\DLG.exe C:\WINDOWS\system32\msdtc.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Andy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.google.com mSearchAssistant = hxxp://www.google.com mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe, BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.5.0.134\IPSBHO.DLL uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [WavXMgr] c:\program files\wave systems corp\services manager\docmgr\bin\WavXDocMgr.exe mRun: [SecureUpgrade] c:\program files\wave systems corp\SecureUpgrade.exe mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe mRun: [KADxMain] c:\windows\system32\KADxMain.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe uPolicies-explorer: ForceClassicControlPanel = 1 (0x1) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1242106997203 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab Notify: gemsafe - c:\program files\gemplus\gemsafe libraries\bin\WLEventNotify.dll LSA: Authentication Packages = msv1_0 wvauth ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\andy\applic~1\mozilla\firefox\profiles\8vj3hm9y.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://aimzones.aol.com/homepage FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query= FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1005000.086\SymEFA.sys [2009-7-20 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1005000.086\BHDrvx86.sys [2009-7-20 258608] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1005000.086\cchpx86.sys [2009-7-20 482352] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090715.003\IDSXpx86.sys [2009-7-20 276344] R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\broadcom\asfipmon\AsfIpMon.exe [2006-12-19 79432] R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2004-8-11 5120] R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [2006-11-2 97536] S2 ukbsetzl;ukbsetzl;\??\c:\windows\system32\drivers\eduyzaoblcqil.sys –> c:\windows\system32\drivers\eduyzaoblcqil.sys [?] S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\viewpoint\common\viewpointservice.exe" –> c:\program files\viewpoint\common\ViewpointService.exe [?] S3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090720.006\NAVENG.SYS [2009-7-20 87888] S3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090720.006\NAVEX15.SYS [2009-7-20 875728] S4 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.5.0.134\ccSvcHst.exe [2009-7-20 115560] =============== Created Last 30 ================ 2009-07-20 00:41 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-20 00:41 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-20 00:41 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-20 00:41 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-20 00:27 36,400 a—-r– c:\windows\system32\drivers\SymIM.sys 2009-07-20 00:27 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-07-20 00:27 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-07-20 00:27 7,386 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-07-20 00:27 805 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-07-20 00:27 –d—– c:\program files\Symantec 2009-07-20 00:27 –d—– c:\windows\system32\drivers\NAV 2009-07-20 00:27 –d—– c:\program files\Norton AntiVirus 2009-07-20 00:26 –d—– c:\program files\NortonInstaller 2009-07-19 23:22 206 a——- c:\windows\system32\MRT.INI 2009-07-19 21:49 –d—– c:\program files\common files\Symantec Shared 2009-07-19 21:48 19,528 a——- c:\windows\system32\yrerov.vbs 2009-07-19 21:48 19,356 a——- c:\windows\rutego.dat 2009-07-19 21:48 17,845 a——- c:\windows\ewito._dl 2009-07-19 21:48 17,797 a——- c:\windows\polumo.lib 2009-07-19 21:48 17,358 a——- c:\windows\system32\edeqar.dl 2009-07-19 21:48 14,754 a——- c:\windows\apytikyhe.bat 2009-07-19 21:48 14,364 a——- c:\windows\duca.inf 2009-07-19 21:48 12,703 a——- c:\windows\ibigawa.db 2009-07-19 21:48 10,914 a——- c:\program files\common files\xyfal.vbs 2009-07-19 21:44 345,228 a——- c:\windows\system32\_scui.cpl 2009-07-19 21:44 –d—– c:\program files\HomeAntivirus2010 2009-07-19 21:26 180,988 a——- c:\windows\system32\wisdstr.exe 2009-07-19 21:21 213,024 a——- c:\windows\system32\drivers\str.sys 2009-07-19 21:21 134 a——- c:\windows\system32\delself.bat 2009-07-12 22:29 24,064 a–sh— c:\documents and settings\andy\protect.dll 2009-07-12 22:28 121,344 a——- c:\windows\msa.exe 2009-07-12 22:28 211,460 a——- c:\windows\system32\msxml71.dll 2009-07-12 21:57 –dsh— c:\documents and settings\andy\PrivacIE 2009-07-12 21:52 –d—– c:\program files\DivX 2009-06-24 20:04 –dsh— c:\documents and settings\andy\IETldCache 2009-06-24 20:02 102,912 ——– c:\windows\system32\dllcache\iecompat.dll 2009-06-24 20:02 –d—– c:\windows\ie8updates 2009-06-24 20:01 11,064,832 ——– c:\windows\system32\dllcache\ieframe.dll 2009-06-24 20:01 1,985,024 ——– c:\windows\system32\dllcache\iertutil.dll 2009-06-24 20:01 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll 2009-06-24 20:01 12,800 ——– c:\windows\system32\dllcache\xpshims.dll 2009-06-24 20:00 -cd-h— c:\windows\ie8 ==================== Find3M ==================== 2009-07-06 14:50 30,082 a——- c:\windows\system32\nvModes.dat 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-13 01:15 915,456 a——- c:\windows\system32\wininet.dll 2009-05-13 01:15 5,936,128 ——– c:\windows\system32\dllcache\mshtml.dll 2009-05-13 01:15 915,456 ——– c:\windows\system32\dllcache\wininet.dll 2009-05-12 02:16 88,867 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-05-12 01:13 356,352 a——- c:\windows\system32\AegisI5Installer.exe 2009-05-12 01:13 21,393 a——- c:\windows\AegisP.sys 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 11:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-30 17:22 1,207,808 ——– c:\windows\system32\dllcache\urlmon.dll 2009-04-30 17:22 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2009-04-30 17:22 385,536 ——– c:\windows\system32\dllcache\iedkcs32.dll 2009-04-30 07:21 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-04-29 00:46 1,499,136 ——– c:\windows\system32\dllcache\shdocvw.dll ============= FINISH: 8:42:49.42 =============== Attach log: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 5/12/2009 1:36:54 AM System Uptime: 7/22/2009 8:36:16 AM (0 hours ago) Motherboard: Dell Inc. | | Processor: Intel® Core™2 Duo CPU T7300 @ 2.00GHz | Microprocessor | 1994/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 112 GiB total, 102.027 GiB free. D: is CDROM () E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== No restore point in system. ==== Installed Programs ====================== Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX AuthenTec Fingerprint Sensor Minimum Install biolsp patch Broadcom ASF Management Applications Broadcom Management Programs Conexant HDA D330 MDC V.92 Modem Dell Drivers MSI Dell Embassy Trust Suite by Wave Systems Dell Touchpad Digital Line Detect Document Manager Lite Download Updater (AOL LLC) EMBASSY Security Center EMBASSY Security Setup EMBASSY Trust Suite by Wave Systems ESC Home Page Plugin Gemalto GemSafe Standard Edition 5.1 High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows XP (KB952287) Intel® PROSet/Wireless Software IntelliSonic Speech Enhancement Java™ 6 Update 5 Malwarebytes' Anti-Malware mCore mDrWiFi mHlpDell Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft VC9 runtime libraries mIWA mLogView mMHouse Modem Diagnostic Tool Mozilla Firefox (3.0.11) mPfMgr mPfWiz mProSafe mSCfg mSSO MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB933579) mWlsSafe mWMI mZConfig NetWaiting Norton AntiVirus NTRU TCG Software Stack NVIDIA Drivers Preboot Manager Private Information Manager QuickSet Secure Update Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) Security Wizards TBS WMP Plug-in Trusted Drive Manager tsp patch Update for Windows Internet Explorer 8 (KB971930) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) upekmsi Ventrilo Client Wave Infrastructure Installer Wave Support Software WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 7/22/2009 8:34:24 AM, error: Service Control Manager [7034] - The Wave UCSPlus service terminated unexpectedly. It has done this 1 time(s). 7/22/2009 8:34:24 AM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine. 7/22/2009 8:34:24 AM, error: Service Control Manager [7001] - The Fast User Switching Compatibility service depends on the Terminal Services service which failed to start because of the following error: The pipe state is invalid. 7/22/2009 8:34:24 AM, error: Service Control Manager [7000] - The Terminal Services service failed to start due to the following error: The pipe state is invalid. 7/20/2009 8:48:58 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV BHDrvx86 ccHP eeCtrl Fips IDSxpx86 intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SRTSPX SYMTDI Tcpip 7/20/2009 8:41:20 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV BHDrvx86 ccHP Fips IDSxpx86 intelppm SRTSPX SYMTDI 7/20/2009 8:41:20 AM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The requested service provider could not be loaded or initialized. 7/20/2009 12:21:25 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 7/20/2009 12:17:54 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: APPDRV BHDrvx86 ccHP eeCtrl Fips IDSxpx86 intelppm SRTSPX SYMTDI 7/19/2009 9:57:18 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep 7/19/2009 9:57:18 PM, error: Service Control Manager [7000] - The Viewpoint Manager Service service failed to start due to the following error: The system cannot find the path specified. 7/19/2009 9:49:42 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0013E8B2318D. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 7/19/2009 9:32:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Viewpoint Manager Service service to connect. 7/19/2009 9:32:19 PM, error: Service Control Manager [7000] - The Viewpoint Manager Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/19/2009 11:37:44 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV Beep BHDrvx86 ccHP eeCtrl Fips IDSxpx86 intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SRTSPX SYMTDI Tcpip 7/19/2009 11:09:51 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD APPDRV Beep BHDrvx86 ccHP Fips IDSxpx86 intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SRTSPX SYMTDI Tcpip 7/19/2009 11:09:51 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 7/19/2009 11:09:51 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/19/2009 11:09:51 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/19/2009 11:09:51 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 7/19/2009 11:09:38 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 7/19/2009 11:09:06 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} ==== End Of File ===========================
renaming GMER worked. Brilliant advice. I wonder if it will work for the other AV tools New problem: The log file is too large for me paste or upload (957kb). Please advise
One more diagnostic tool, sorry DAM-D.

Download RootRepeal and save it to your desktop.
  • Extract RootRepeal.exe from the zip archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all six boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, click the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.

If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.
One or more of the identified infections is known as an "info stealer"

This type of infection has the ability to steal personal information from your computer.
As a precaution, from a clean computer, change all your passwords.
It would also be wise to contact your financial institutions to appraise them of your situation.
Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?

I can clean this computer, but obviously cannot guarantee it will be 100% trustworthy again, only a reformat/reinstall will do that. Please advise.

If you wish to continue cleaning - please do the following:

Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on Combo-Fix.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/Cannot_start_any_anti_virus_scan_tools_t105430.html
    
    Collect:: 
    c:\windows\system32\yrerov.vbs
    c:\windows\rutego.dat
    c:\documents and settings\Andy\Local Settings\Application Data\ehiker.pif
    c:\windows\apytikyhe.bat
    c:\program files\Common Files\xyfal.vbs
    c:\windows\system32\wisdstr.exe
    c:\windows\system32\drivers\eduyzaoblcqil.sys
    
    Folder::
    c:\program files\HomeAntivirus2010
    
    Driver:: 
    ukbsetzl
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Sorry, I was away for the weekend. The solution you provided worked. Well Done! After Combo-Fix I was able to run the other antivirus tools that I had downloaded. I ran Malware, then SmitFraud, then Norton and was able to remove all the other virus'. What can I contribute to this posting in the way of log files to bring this to a conclusion? -DM

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI